diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md
index ffd0a28..d96ed73 100644
--- a/.github/CONTRIBUTING.md
+++ b/.github/CONTRIBUTING.md
@@ -33,3 +33,20 @@ class="machine_readable/">.machine_readable/.
All contributors are expected to adhere to our ethical standards. See
CODE_OF_CONDUCT for details.
+
+## Signed commits
+
+Every commit that reaches the default branch must be signed; a ruleset refuses
+unsigned pushes. Estate policy:
+[SIGNING-POLICY](https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc).
+
+- **People and interactive agents** sign with an SSH key registered on GitHub
+ as a *signing* key (`gpg.format=ssh`, `user.signingkey=.pub`,
+ `commit.gpgsign=true`). The committer email must be verified on that account.
+- **Apps, bots and workflows** never `git push` local commits. They write
+ through the API (`createCommitOnBranch` or the estate `signed-push` action)
+ so that GitHub signs each commit.
+- Merge PRs with **squash**. The ruleset checks every commit on the PR branch,
+ not just the result, so one unsigned commit blocks the merge. Re-create such a
+ branch with signed commits (`git cherry-pick -S`) and open a new PR.
+ Rebase-merge replays commits unsigned and is disabled.